PT-2021-15559 · Flatcore · Flatcore

Published

2021-01-15

·

Updated

2021-01-22

·

CVE-2021-23838

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: flatCore versions prior to 2.0.0 build 139
Description: A reflected XSS issue was identified in the media filter HTTP request body parameter for the acp interface. This parameter accepts malicious client-side script without proper input sanitization, allowing a malicious user to steal cookies from a victim user and perform a session-hijacking attack, potentially leading to unauthorized access to the site.
Recommendations: For versions prior to 2.0.0 build 139, update to a version 2.0.0 build 139 or later to resolve the issue. As a temporary workaround, consider restricting access to the media filter parameter in the acp interface to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23838

Affected Products

Flatcore